Closed pbssubhash closed 3 years ago
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
Knock Knock.. Any luck gentlemen? Care to reply?
This does not appear to be a bug. Let's take the conversaion up on Discuss.
Discussion Forum Link: https://discuss.elastic.co/t/hostname-and-timestamp-gets-overwritten-when-using-archived-event-logs-using-winlogbeat/257739 Version : Winlogbeat 7.9.2 Platform: Windows 10 Reproduction Instructions: Use winlogbeat to upload an event log file (.evtx file using -E option) and use the default config file. I used this script to upload bulk files from https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES as a test. All my host.name values are overwritten with the name of the machine used for uploading and corresponding timestamp's also overwritten. I've tried inline script processors to replace host.name but no luck.
My full config file.